Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Kaffe_openvm | Kaffe | 1.0.6 (including) | 1.0.6 (including) |